PT0-002 Attacks and Exploits Practice Question
A tester is using Hashcat to crack NTLM hashes. They want to try all possible passwords consisting of exactly 8 lowercase letters. Which attack mode and mask should they use?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
-a 3 -m 1000 ?l?l?l?l?l?l?l?l
Brute-force mode (-a 3) with mask ?l?l?l?l?l?l?l?l tries all 8-letter lowercase combinations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
-a 6 -m 1000 ?l?l?l?l?l?l?l?l
Why it's wrong here
Using -a 6 invokes hashcat's hybrid attack, not brute-force. This mode expects a wordlist file and appends the specified mask to each dictionary word, so it would try combinations like a dictionary word followed by an 8-character lowercase string rather than every possible 8-character lowercase combination. Without a wordlist file, the command is also incomplete, and it will not enumerate the full 26^8 keyspace the tester intends.
- ✗
-a 3 -m 0 ?l?l?l?l?l?l?l?l
Why it's wrong here
-a 3 correctly selects a pure brute-force mask attack, but -m 0 tells Hashcat to treat the target hashes as raw MD5. NTLM hashes are not MD5; they are the NT hash, which is an MD4-based digest of the UTF-16LE encoded password, and Hashcat identifies them with mode 1000. Using -m 0 would therefore fail to recognize the NTLM hash type and would attempt the mask against MD5 digests, so the command cannot crack the intended hashes.
- ✓
-a 3 -m 1000 ?l?l?l?l?l?l?l?l
Why this is correct
The correct answer combines attack mode 3 with NTLM hash mode 1000. Hashcat's attack mode 3 is a pure brute-force or mask attack, and the mask ?l?l?l?l?l?l?l?l systematically generates every 8-character string consisting of lowercase letters a through z. Any NTLM hash whose password matches that pattern will be recovered because the entire keyspace of 26^8 is exhaustively searched.
- ✗
-a 0 -m 1000 dictionary.txt
Why it's wrong here
With -a 0, Hashcat runs a dictionary attack, reading each line of dictionary.txt and checking it against the NTLM hashes. This is not brute-force because it never generates passwords outside the wordlist; only passwords that exactly match an entry in dictionary.txt will be cracked. Additionally, the dictionary file may not contain all 8-lowercase-letter combinations, so the key space is not systematically explored.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.